{
  "name": "first_epss",
  "title": "First EPSS",
  "version": "1.6.0",
  "release": "ga",
  "description": "Collect exploit prediction score data from the First EPSS API with Elastic Agent.",
  "type": "integration",
  "download": "/epr/first_epss/first_epss-1.6.0.zip",
  "path": "/package/first_epss/1.6.0",
  "icons": [
    {
      "src": "/img/first-org-RGB.svg",
      "path": "/package/first_epss/1.6.0/img/first-org-RGB.svg",
      "title": "First logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.2 || ^9.0.5"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "community",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "vulnerability_management"
  ],
  "signature_path": "/epr/first_epss/first_epss-1.6.0.zip.sig",
  "format_version": "3.6.6",
  "readme": "/package/first_epss/1.6.0/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/first-epss-dashboard.png",
      "path": "/package/first_epss/1.6.0/img/first-epss-dashboard.png",
      "title": "First EPSS Dashboard",
      "size": "1988x1792",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/first_epss/1.6.0/LICENSE.txt",
    "/package/first_epss/1.6.0/changelog.yml",
    "/package/first_epss/1.6.0/manifest.yml",
    "/package/first_epss/1.6.0/docs/README.md",
    "/package/first_epss/1.6.0/img/first-epss-dashboard.png",
    "/package/first_epss/1.6.0/img/first-org-RGB.svg",
    "/package/first_epss/1.6.0/data_stream/vulnerability/manifest.yml",
    "/package/first_epss/1.6.0/data_stream/vulnerability/sample_event.json",
    "/package/first_epss/1.6.0/kibana/dashboard/first_epss-fad8ebfb-fb41-4029-bbcb-c8e05d7f6c65.json",
    "/package/first_epss/1.6.0/data_stream/vulnerability/fields/base-fields.yml",
    "/package/first_epss/1.6.0/data_stream/vulnerability/fields/beats.yml",
    "/package/first_epss/1.6.0/data_stream/vulnerability/fields/ecs.yml",
    "/package/first_epss/1.6.0/data_stream/vulnerability/fields/fields.yml",
    "/package/first_epss/1.6.0/data_stream/vulnerability/fields/is-transform-source-true.yml",
    "/package/first_epss/1.6.0/elasticsearch/transform/latest_vulnerability/manifest.yml",
    "/package/first_epss/1.6.0/elasticsearch/transform/latest_vulnerability/transform.yml",
    "/package/first_epss/1.6.0/data_stream/vulnerability/agent/stream/cel.yml.hbs",
    "/package/first_epss/1.6.0/data_stream/vulnerability/elasticsearch/ingest_pipeline/default.yml",
    "/package/first_epss/1.6.0/elasticsearch/transform/latest_vulnerability/fields/base-fields.yml",
    "/package/first_epss/1.6.0/elasticsearch/transform/latest_vulnerability/fields/beats.yml",
    "/package/first_epss/1.6.0/elasticsearch/transform/latest_vulnerability/fields/ecs.yml",
    "/package/first_epss/1.6.0/elasticsearch/transform/latest_vulnerability/fields/fields.yml",
    "/package/first_epss/1.6.0/elasticsearch/transform/latest_vulnerability/fields/is-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "first_epss",
      "title": "First EPSS data",
      "description": "Collect First EPSS data.",
      "inputs": [
        {
          "type": "cel",
          "vars": [
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            }
          ],
          "title": "Collect First EPSS data via API",
          "description": "Collect First EPSS data via API."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "first_epss.vulnerability",
      "title": "Collect EPSS data from First API.",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "URL",
              "description": "Base URL of the First EPSS API.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://api.first.org/data/v1/epss"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval between two REST API calls. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Batch size for the response of the First EPSS API. Should be a number between 1 and 100 (https://api.first.org/#Global-parameters).",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 100
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Give a timeout of more than 1 minute when retrieving data which is more than 15 days old. Supported time units are ns, us, ms, s, m, h. Requests may take significant time, so short timeouts are not recommended.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "10m"
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the data is parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_filename) for details.\n",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "First EPSS data",
          "description": "Collect EPSS data from First API.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "first_epss",
      "path": "vulnerability"
    }
  ]
}
